Update test location
This commit is contained in:
parent
87d0fda4c1
commit
2d5037a8fb
22 changed files with 1 additions and 1702 deletions
46
COMMITMENT
46
COMMITMENT
|
|
@ -1,46 +0,0 @@
|
|||
GPL Cooperation Commitment
|
||||
Version 1.0
|
||||
|
||||
Before filing or continuing to prosecute any legal proceeding or claim
|
||||
(other than a Defensive Action) arising from termination of a Covered
|
||||
License, we commit to extend to the person or entity ('you') accused
|
||||
of violating the Covered License the following provisions regarding
|
||||
cure and reinstatement, taken from GPL version 3. As used here, the
|
||||
term 'this License' refers to the specific Covered License being
|
||||
enforced.
|
||||
|
||||
However, if you cease all violation of this License, then your
|
||||
license from a particular copyright holder is reinstated (a)
|
||||
provisionally, unless and until the copyright holder explicitly
|
||||
and finally terminates your license, and (b) permanently, if the
|
||||
copyright holder fails to notify you of the violation by some
|
||||
reasonable means prior to 60 days after the cessation.
|
||||
|
||||
Moreover, your license from a particular copyright holder is
|
||||
reinstated permanently if the copyright holder notifies you of the
|
||||
violation by some reasonable means, this is the first time you
|
||||
have received notice of violation of this License (for any work)
|
||||
from that copyright holder, and you cure the violation prior to 30
|
||||
days after your receipt of the notice.
|
||||
|
||||
We intend this Commitment to be irrevocable, and binding and
|
||||
enforceable against us and assignees of or successors to our
|
||||
copyrights.
|
||||
|
||||
Definitions
|
||||
|
||||
'Covered License' means the GNU General Public License, version 2
|
||||
(GPLv2), the GNU Lesser General Public License, version 2.1
|
||||
(LGPLv2.1), or the GNU Library General Public License, version 2
|
||||
(LGPLv2), all as published by the Free Software Foundation.
|
||||
|
||||
'Defensive Action' means a legal proceeding or claim that We bring
|
||||
against you in response to a prior proceeding or claim initiated by
|
||||
you or your affiliate.
|
||||
|
||||
'We' means each contributor to this repository as of the date of
|
||||
inclusion of this file, including subsidiaries of a corporate
|
||||
contributor.
|
||||
|
||||
This work is available under a Creative Commons Attribution-ShareAlike
|
||||
4.0 International license (https://creativecommons.org/licenses/by-sa/4.0/).
|
||||
339
LICENSE
339
LICENSE
|
|
@ -1,339 +0,0 @@
|
|||
GNU GENERAL PUBLIC LICENSE
|
||||
Version 2, June 1991
|
||||
|
||||
Copyright (C) 1989, 1991 Free Software Foundation, Inc.,
|
||||
51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
|
||||
Everyone is permitted to copy and distribute verbatim copies
|
||||
of this license document, but changing it is not allowed.
|
||||
|
||||
Preamble
|
||||
|
||||
The licenses for most software are designed to take away your
|
||||
freedom to share and change it. By contrast, the GNU General Public
|
||||
License is intended to guarantee your freedom to share and change free
|
||||
software--to make sure the software is free for all its users. This
|
||||
General Public License applies to most of the Free Software
|
||||
Foundation's software and to any other program whose authors commit to
|
||||
using it. (Some other Free Software Foundation software is covered by
|
||||
the GNU Lesser General Public License instead.) You can apply it to
|
||||
your programs, too.
|
||||
|
||||
When we speak of free software, we are referring to freedom, not
|
||||
price. Our General Public Licenses are designed to make sure that you
|
||||
have the freedom to distribute copies of free software (and charge for
|
||||
this service if you wish), that you receive source code or can get it
|
||||
if you want it, that you can change the software or use pieces of it
|
||||
in new free programs; and that you know you can do these things.
|
||||
|
||||
To protect your rights, we need to make restrictions that forbid
|
||||
anyone to deny you these rights or to ask you to surrender the rights.
|
||||
These restrictions translate to certain responsibilities for you if you
|
||||
distribute copies of the software, or if you modify it.
|
||||
|
||||
For example, if you distribute copies of such a program, whether
|
||||
gratis or for a fee, you must give the recipients all the rights that
|
||||
you have. You must make sure that they, too, receive or can get the
|
||||
source code. And you must show them these terms so they know their
|
||||
rights.
|
||||
|
||||
We protect your rights with two steps: (1) copyright the software, and
|
||||
(2) offer you this license which gives you legal permission to copy,
|
||||
distribute and/or modify the software.
|
||||
|
||||
Also, for each author's protection and ours, we want to make certain
|
||||
that everyone understands that there is no warranty for this free
|
||||
software. If the software is modified by someone else and passed on, we
|
||||
want its recipients to know that what they have is not the original, so
|
||||
that any problems introduced by others will not reflect on the original
|
||||
authors' reputations.
|
||||
|
||||
Finally, any free program is threatened constantly by software
|
||||
patents. We wish to avoid the danger that redistributors of a free
|
||||
program will individually obtain patent licenses, in effect making the
|
||||
program proprietary. To prevent this, we have made it clear that any
|
||||
patent must be licensed for everyone's free use or not licensed at all.
|
||||
|
||||
The precise terms and conditions for copying, distribution and
|
||||
modification follow.
|
||||
|
||||
GNU GENERAL PUBLIC LICENSE
|
||||
TERMS AND CONDITIONS FOR COPYING, DISTRIBUTION AND MODIFICATION
|
||||
|
||||
0. This License applies to any program or other work which contains
|
||||
a notice placed by the copyright holder saying it may be distributed
|
||||
under the terms of this General Public License. The "Program", below,
|
||||
refers to any such program or work, and a "work based on the Program"
|
||||
means either the Program or any derivative work under copyright law:
|
||||
that is to say, a work containing the Program or a portion of it,
|
||||
either verbatim or with modifications and/or translated into another
|
||||
language. (Hereinafter, translation is included without limitation in
|
||||
the term "modification".) Each licensee is addressed as "you".
|
||||
|
||||
Activities other than copying, distribution and modification are not
|
||||
covered by this License; they are outside its scope. The act of
|
||||
running the Program is not restricted, and the output from the Program
|
||||
is covered only if its contents constitute a work based on the
|
||||
Program (independent of having been made by running the Program).
|
||||
Whether that is true depends on what the Program does.
|
||||
|
||||
1. You may copy and distribute verbatim copies of the Program's
|
||||
source code as you receive it, in any medium, provided that you
|
||||
conspicuously and appropriately publish on each copy an appropriate
|
||||
copyright notice and disclaimer of warranty; keep intact all the
|
||||
notices that refer to this License and to the absence of any warranty;
|
||||
and give any other recipients of the Program a copy of this License
|
||||
along with the Program.
|
||||
|
||||
You may charge a fee for the physical act of transferring a copy, and
|
||||
you may at your option offer warranty protection in exchange for a fee.
|
||||
|
||||
2. You may modify your copy or copies of the Program or any portion
|
||||
of it, thus forming a work based on the Program, and copy and
|
||||
distribute such modifications or work under the terms of Section 1
|
||||
above, provided that you also meet all of these conditions:
|
||||
|
||||
a) You must cause the modified files to carry prominent notices
|
||||
stating that you changed the files and the date of any change.
|
||||
|
||||
b) You must cause any work that you distribute or publish, that in
|
||||
whole or in part contains or is derived from the Program or any
|
||||
part thereof, to be licensed as a whole at no charge to all third
|
||||
parties under the terms of this License.
|
||||
|
||||
c) If the modified program normally reads commands interactively
|
||||
when run, you must cause it, when started running for such
|
||||
interactive use in the most ordinary way, to print or display an
|
||||
announcement including an appropriate copyright notice and a
|
||||
notice that there is no warranty (or else, saying that you provide
|
||||
a warranty) and that users may redistribute the program under
|
||||
these conditions, and telling the user how to view a copy of this
|
||||
License. (Exception: if the Program itself is interactive but
|
||||
does not normally print such an announcement, your work based on
|
||||
the Program is not required to print an announcement.)
|
||||
|
||||
These requirements apply to the modified work as a whole. If
|
||||
identifiable sections of that work are not derived from the Program,
|
||||
and can be reasonably considered independent and separate works in
|
||||
themselves, then this License, and its terms, do not apply to those
|
||||
sections when you distribute them as separate works. But when you
|
||||
distribute the same sections as part of a whole which is a work based
|
||||
on the Program, the distribution of the whole must be on the terms of
|
||||
this License, whose permissions for other licensees extend to the
|
||||
entire whole, and thus to each and every part regardless of who wrote it.
|
||||
|
||||
Thus, it is not the intent of this section to claim rights or contest
|
||||
your rights to work written entirely by you; rather, the intent is to
|
||||
exercise the right to control the distribution of derivative or
|
||||
collective works based on the Program.
|
||||
|
||||
In addition, mere aggregation of another work not based on the Program
|
||||
with the Program (or with a work based on the Program) on a volume of
|
||||
a storage or distribution medium does not bring the other work under
|
||||
the scope of this License.
|
||||
|
||||
3. You may copy and distribute the Program (or a work based on it,
|
||||
under Section 2) in object code or executable form under the terms of
|
||||
Sections 1 and 2 above provided that you also do one of the following:
|
||||
|
||||
a) Accompany it with the complete corresponding machine-readable
|
||||
source code, which must be distributed under the terms of Sections
|
||||
1 and 2 above on a medium customarily used for software interchange; or,
|
||||
|
||||
b) Accompany it with a written offer, valid for at least three
|
||||
years, to give any third party, for a charge no more than your
|
||||
cost of physically performing source distribution, a complete
|
||||
machine-readable copy of the corresponding source code, to be
|
||||
distributed under the terms of Sections 1 and 2 above on a medium
|
||||
customarily used for software interchange; or,
|
||||
|
||||
c) Accompany it with the information you received as to the offer
|
||||
to distribute corresponding source code. (This alternative is
|
||||
allowed only for noncommercial distribution and only if you
|
||||
received the program in object code or executable form with such
|
||||
an offer, in accord with Subsection b above.)
|
||||
|
||||
The source code for a work means the preferred form of the work for
|
||||
making modifications to it. For an executable work, complete source
|
||||
code means all the source code for all modules it contains, plus any
|
||||
associated interface definition files, plus the scripts used to
|
||||
control compilation and installation of the executable. However, as a
|
||||
special exception, the source code distributed need not include
|
||||
anything that is normally distributed (in either source or binary
|
||||
form) with the major components (compiler, kernel, and so on) of the
|
||||
operating system on which the executable runs, unless that component
|
||||
itself accompanies the executable.
|
||||
|
||||
If distribution of executable or object code is made by offering
|
||||
access to copy from a designated place, then offering equivalent
|
||||
access to copy the source code from the same place counts as
|
||||
distribution of the source code, even though third parties are not
|
||||
compelled to copy the source along with the object code.
|
||||
|
||||
4. You may not copy, modify, sublicense, or distribute the Program
|
||||
except as expressly provided under this License. Any attempt
|
||||
otherwise to copy, modify, sublicense or distribute the Program is
|
||||
void, and will automatically terminate your rights under this License.
|
||||
However, parties who have received copies, or rights, from you under
|
||||
this License will not have their licenses terminated so long as such
|
||||
parties remain in full compliance.
|
||||
|
||||
5. You are not required to accept this License, since you have not
|
||||
signed it. However, nothing else grants you permission to modify or
|
||||
distribute the Program or its derivative works. These actions are
|
||||
prohibited by law if you do not accept this License. Therefore, by
|
||||
modifying or distributing the Program (or any work based on the
|
||||
Program), you indicate your acceptance of this License to do so, and
|
||||
all its terms and conditions for copying, distributing or modifying
|
||||
the Program or works based on it.
|
||||
|
||||
6. Each time you redistribute the Program (or any work based on the
|
||||
Program), the recipient automatically receives a license from the
|
||||
original licensor to copy, distribute or modify the Program subject to
|
||||
these terms and conditions. You may not impose any further
|
||||
restrictions on the recipients' exercise of the rights granted herein.
|
||||
You are not responsible for enforcing compliance by third parties to
|
||||
this License.
|
||||
|
||||
7. If, as a consequence of a court judgment or allegation of patent
|
||||
infringement or for any other reason (not limited to patent issues),
|
||||
conditions are imposed on you (whether by court order, agreement or
|
||||
otherwise) that contradict the conditions of this License, they do not
|
||||
excuse you from the conditions of this License. If you cannot
|
||||
distribute so as to satisfy simultaneously your obligations under this
|
||||
License and any other pertinent obligations, then as a consequence you
|
||||
may not distribute the Program at all. For example, if a patent
|
||||
license would not permit royalty-free redistribution of the Program by
|
||||
all those who receive copies directly or indirectly through you, then
|
||||
the only way you could satisfy both it and this License would be to
|
||||
refrain entirely from distribution of the Program.
|
||||
|
||||
If any portion of this section is held invalid or unenforceable under
|
||||
any particular circumstance, the balance of the section is intended to
|
||||
apply and the section as a whole is intended to apply in other
|
||||
circumstances.
|
||||
|
||||
It is not the purpose of this section to induce you to infringe any
|
||||
patents or other property right claims or to contest validity of any
|
||||
such claims; this section has the sole purpose of protecting the
|
||||
integrity of the free software distribution system, which is
|
||||
implemented by public license practices. Many people have made
|
||||
generous contributions to the wide range of software distributed
|
||||
through that system in reliance on consistent application of that
|
||||
system; it is up to the author/donor to decide if he or she is willing
|
||||
to distribute software through any other system and a licensee cannot
|
||||
impose that choice.
|
||||
|
||||
This section is intended to make thoroughly clear what is believed to
|
||||
be a consequence of the rest of this License.
|
||||
|
||||
8. If the distribution and/or use of the Program is restricted in
|
||||
certain countries either by patents or by copyrighted interfaces, the
|
||||
original copyright holder who places the Program under this License
|
||||
may add an explicit geographical distribution limitation excluding
|
||||
those countries, so that distribution is permitted only in or among
|
||||
countries not thus excluded. In such case, this License incorporates
|
||||
the limitation as if written in the body of this License.
|
||||
|
||||
9. The Free Software Foundation may publish revised and/or new versions
|
||||
of the General Public License from time to time. Such new versions will
|
||||
be similar in spirit to the present version, but may differ in detail to
|
||||
address new problems or concerns.
|
||||
|
||||
Each version is given a distinguishing version number. If the Program
|
||||
specifies a version number of this License which applies to it and "any
|
||||
later version", you have the option of following the terms and conditions
|
||||
either of that version or of any later version published by the Free
|
||||
Software Foundation. If the Program does not specify a version number of
|
||||
this License, you may choose any version ever published by the Free Software
|
||||
Foundation.
|
||||
|
||||
10. If you wish to incorporate parts of the Program into other free
|
||||
programs whose distribution conditions are different, write to the author
|
||||
to ask for permission. For software which is copyrighted by the Free
|
||||
Software Foundation, write to the Free Software Foundation; we sometimes
|
||||
make exceptions for this. Our decision will be guided by the two goals
|
||||
of preserving the free status of all derivatives of our free software and
|
||||
of promoting the sharing and reuse of software generally.
|
||||
|
||||
NO WARRANTY
|
||||
|
||||
11. BECAUSE THE PROGRAM IS LICENSED FREE OF CHARGE, THERE IS NO WARRANTY
|
||||
FOR THE PROGRAM, TO THE EXTENT PERMITTED BY APPLICABLE LAW. EXCEPT WHEN
|
||||
OTHERWISE STATED IN WRITING THE COPYRIGHT HOLDERS AND/OR OTHER PARTIES
|
||||
PROVIDE THE PROGRAM "AS IS" WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESSED
|
||||
OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF
|
||||
MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. THE ENTIRE RISK AS
|
||||
TO THE QUALITY AND PERFORMANCE OF THE PROGRAM IS WITH YOU. SHOULD THE
|
||||
PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF ALL NECESSARY SERVICING,
|
||||
REPAIR OR CORRECTION.
|
||||
|
||||
12. IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING
|
||||
WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MAY MODIFY AND/OR
|
||||
REDISTRIBUTE THE PROGRAM AS PERMITTED ABOVE, BE LIABLE TO YOU FOR DAMAGES,
|
||||
INCLUDING ANY GENERAL, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES ARISING
|
||||
OUT OF THE USE OR INABILITY TO USE THE PROGRAM (INCLUDING BUT NOT LIMITED
|
||||
TO LOSS OF DATA OR DATA BEING RENDERED INACCURATE OR LOSSES SUSTAINED BY
|
||||
YOU OR THIRD PARTIES OR A FAILURE OF THE PROGRAM TO OPERATE WITH ANY OTHER
|
||||
PROGRAMS), EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE
|
||||
POSSIBILITY OF SUCH DAMAGES.
|
||||
|
||||
END OF TERMS AND CONDITIONS
|
||||
|
||||
How to Apply These Terms to Your New Programs
|
||||
|
||||
If you develop a new program, and you want it to be of the greatest
|
||||
possible use to the public, the best way to achieve this is to make it
|
||||
free software which everyone can redistribute and change under these terms.
|
||||
|
||||
To do so, attach the following notices to the program. It is safest
|
||||
to attach them to the start of each source file to most effectively
|
||||
convey the exclusion of warranty; and each file should have at least
|
||||
the "copyright" line and a pointer to where the full notice is found.
|
||||
|
||||
<one line to give the program's name and a brief idea of what it does.>
|
||||
Copyright (C) <year> <name of author>
|
||||
|
||||
This program is free software; you can redistribute it and/or modify
|
||||
it under the terms of the GNU General Public License as published by
|
||||
the Free Software Foundation; either version 2 of the License, or
|
||||
(at your option) any later version.
|
||||
|
||||
This program is distributed in the hope that it will be useful,
|
||||
but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||
GNU General Public License for more details.
|
||||
|
||||
You should have received a copy of the GNU General Public License along
|
||||
with this program; if not, write to the Free Software Foundation, Inc.,
|
||||
51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||
|
||||
Also add information on how to contact you by electronic and paper mail.
|
||||
|
||||
If the program is interactive, make it output a short notice like this
|
||||
when it starts in an interactive mode:
|
||||
|
||||
Gnomovision version 69, Copyright (C) year name of author
|
||||
Gnomovision comes with ABSOLUTELY NO WARRANTY; for details type `show w'.
|
||||
This is free software, and you are welcome to redistribute it
|
||||
under certain conditions; type `show c' for details.
|
||||
|
||||
The hypothetical commands `show w' and `show c' should show the appropriate
|
||||
parts of the General Public License. Of course, the commands you use may
|
||||
be called something other than `show w' and `show c'; they could even be
|
||||
mouse-clicks or menu items--whatever suits your program.
|
||||
|
||||
You should also get your employer (if you work as a programmer) or your
|
||||
school, if any, to sign a "copyright disclaimer" for the program, if
|
||||
necessary. Here is a sample; alter the names:
|
||||
|
||||
Yoyodyne, Inc., hereby disclaims all copyright interest in the program
|
||||
`Gnomovision' (which makes passes at compilers) written by James Hacker.
|
||||
|
||||
<signature of Ty Coon>, 1 April 1989
|
||||
Ty Coon, President of Vice
|
||||
|
||||
This General Public License does not permit incorporating your program into
|
||||
proprietary programs. If your program is a subroutine library, you may
|
||||
consider it more useful to permit linking proprietary applications with the
|
||||
library. If this is what you want to do, use the GNU Lesser General
|
||||
Public License instead of this License.
|
||||
|
|
@ -1,3 +1 @@
|
|||
# vsftpd
|
||||
|
||||
repository for vsftpd CI tests
|
||||
Public test have been moved to: https://gitlab.com/redhat/centos-stream/tests/
|
||||
|
|
|
|||
|
|
@ -1,18 +0,0 @@
|
|||
summary: RHEL-45022 - vsftpd FEAT does not show AUTH TLS when using ssl_tlsv1_3=YES
|
||||
description: Test for vsftpd FEAT does not show AUTH TLS when using ssl_tlsv1_3=YES
|
||||
test: ./runtest.sh
|
||||
framework: beakerlib
|
||||
duration: 5m
|
||||
enabled: true
|
||||
tag:
|
||||
- Tier2
|
||||
tier: '2'
|
||||
component:
|
||||
- vsftpd
|
||||
recommend:
|
||||
- vsftpd
|
||||
- lftp
|
||||
- openssl
|
||||
extra-nitrate: TC#0617719
|
||||
id: 958c2496-48cb-4bf6-ae46-94dfb485a5f1
|
||||
author: Ondrej Mejzlik <omejzlik@redhat.com>
|
||||
|
|
@ -1,55 +0,0 @@
|
|||
#!/bin/bash
|
||||
# vim: dict+=/usr/share/beakerlib/dictionary.vim cpt=.,w,b,u,t,i,k
|
||||
# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||
#
|
||||
# runtest.sh of /CoreOS/libfaketime/basic-sanity
|
||||
# Description: Test for basic-sanity
|
||||
# Author: Ondrej Mejzlik <omejzlik@redhat.com>
|
||||
#
|
||||
# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||
#
|
||||
# Copyright (c) 2024 Red Hat, Inc.
|
||||
#
|
||||
# This program is free software: you can redistribute it and/or
|
||||
# modify it under the terms of the GNU General Public License as
|
||||
# published by the Free Software Foundation, either version 2 of
|
||||
# the License, or (at your option) any later version.
|
||||
#
|
||||
# This program is distributed in the hope that it will be
|
||||
# useful, but WITHOUT ANY WARRANTY; without even the implied
|
||||
# warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR
|
||||
# PURPOSE. See the GNU General Public License for more details.
|
||||
#
|
||||
# You should have received a copy of the GNU General Public License
|
||||
# along with this program. If not, see http://www.gnu.org/licenses/.
|
||||
#
|
||||
# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||
|
||||
# Include Beaker environment
|
||||
. /usr/share/beakerlib/beakerlib.sh || exit 1
|
||||
|
||||
PACKAGE=${PACKAGE:-vsftpd}
|
||||
|
||||
rlJournalStart
|
||||
rlPhaseStartSetup
|
||||
rlAssertRpm $PACKAGE || rlDie "Package $PACKAGE not installed"
|
||||
rlLog "Arch: $(arch), PC name: $(hostname), $(hostname -A) User: $(whoami)"
|
||||
rlRun "tmp=\$(mktemp -d)" 0 "Create tmp directory"
|
||||
rlRun "pushd $tmp"
|
||||
rlFileBackup /etc/vsftpd
|
||||
rlPhaseEnd
|
||||
|
||||
rlPhaseStartTest
|
||||
rlRun "printf 'ssl_enable=YES\nssl_tlsv1_3=YES\nrsa_cert_file=/etc/vsftpd/vsftpd.pem\nrsa_private_key_file=/etc/vsftpd/vsftpd.pem\n' >> /etc/vsftpd/vsftpd.conf" 0 "Configuring vstfpd"
|
||||
rlRun "openssl req -x509 -nodes -days 365 -newkey rsa:2048 -subj '/C=US/ST=/L=/O=/OU=/CN=/emailAddress=' -keyout /etc/vsftpd/vsftpd.pem -out /etc/vsftpd/vsftpd.pem" 0 "Creating certificate and key"
|
||||
rlServiceStart vsftpd
|
||||
rlRun "lftp -e 'debug 13; set ftp:trust-feat yes; ls;' username@localhost --password whatever 2>&1 | grep 'AUTH TLS'" 0 "trying to execute command"
|
||||
rlPhaseEnd
|
||||
|
||||
rlPhaseStartCleanup
|
||||
rlFileRestore
|
||||
rlServiceRestore
|
||||
rlRun "popd"
|
||||
rlRun "rm -r $tmp" 0 "Remove tmp directory"
|
||||
rlPhaseEnd
|
||||
rlJournalEnd
|
||||
|
|
@ -1,36 +0,0 @@
|
|||
summary: Test for BZ#809450 (EADDRINUSE return from vsf_sysutil_listen() in)
|
||||
description: |
|
||||
Bug summary: EADDRINUSE return from vsf_sysutil_listen() in handle_pasv() should be handled properly
|
||||
Bugzilla link: https://bugzilla.redhat.com/show_bug.cgi?id=809450
|
||||
Test for BZ#809450 (EADDRINUSE return from vsf_sysutil_listen() in)
|
||||
component:
|
||||
- vsftpd
|
||||
test: ./runtest.sh
|
||||
framework: beakerlib
|
||||
require:
|
||||
- library(distribution/dpcommon)
|
||||
recommend:
|
||||
- vsftpd
|
||||
- nc
|
||||
- ftp
|
||||
- expect
|
||||
duration: 35m
|
||||
enabled: true
|
||||
tag:
|
||||
- NoRHEL4
|
||||
- NoRHEL5
|
||||
- NoRHEL6
|
||||
- Tier1
|
||||
tier: '1'
|
||||
link:
|
||||
- relates: https://bugzilla.redhat.com/show_bug.cgi?id=1309563
|
||||
- relates: https://bugzilla.redhat.com/show_bug.cgi?id=1318198
|
||||
adjust:
|
||||
- enabled: false
|
||||
when: distro == rhel-4, rhel-5, rhel-6
|
||||
continue: false
|
||||
extra-nitrate: TC#0517653
|
||||
extra-summary: /CoreOS/vsftpd/Sanity/500-OOPS-vsf_sysutil_bind-while-passive-port-occupied
|
||||
extra-task: /CoreOS/vsftpd/Sanity/500-OOPS-vsf_sysutil_bind-while-passive-port-occupied
|
||||
id: e4317ddf-6cc6-47dc-8844-c146d99311fc
|
||||
author: Dalibor Pospisil <dapospis@redhat.com>
|
||||
|
|
@ -1,149 +0,0 @@
|
|||
#!/bin/bash
|
||||
# vim: dict=/usr/share/beakerlib/dictionary.vim cpt=.,w,b,u,t,i,k
|
||||
# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||
#
|
||||
# runtest.sh of /CoreOS/vsftpd/Sanity/500-OOPS-vsf_sysutil_bind-while-passive-port-occupied
|
||||
# Description: Test for BZ#809450 (EADDRINUSE return from vsf_sysutil_listen() in)
|
||||
# Author: Dalibor Pospisil <dapospis@redhat.com>
|
||||
#
|
||||
# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||
#
|
||||
# Copyright (c) 2012 Red Hat, Inc. All rights reserved.
|
||||
#
|
||||
# This copyrighted material is made available to anyone wishing
|
||||
# to use, modify, copy, or redistribute it subject to the terms
|
||||
# and conditions of the GNU General Public License version 2.
|
||||
#
|
||||
# This program is distributed in the hope that it will be
|
||||
# useful, but WITHOUT ANY WARRANTY; without even the implied
|
||||
# warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR
|
||||
# PURPOSE. See the GNU General Public License for more details.
|
||||
#
|
||||
# You should have received a copy of the GNU General Public
|
||||
# License along with this program; if not, write to the Free
|
||||
# Software Foundation, Inc., 51 Franklin Street, Fifth Floor,
|
||||
# Boston, MA 02110-1301, USA.
|
||||
#
|
||||
# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||
|
||||
# Include Beaker environment
|
||||
. /usr/share/beakerlib/beakerlib.sh
|
||||
|
||||
PACKAGES="vsftpd ftp expect"
|
||||
BINARIES="nc"
|
||||
PASSWORD="T4jn3h3s10"
|
||||
|
||||
clean_up() {
|
||||
tcfChk "Cleanup phase" && {
|
||||
rlFileRestore
|
||||
tcfChk "stop listening to those ports" &&{
|
||||
while jobs |grep -q -i '+ *running *nc'; do kill %+; jobs >/dev/null; done
|
||||
tcfFin; }
|
||||
# save/restore boolean state only when it is available
|
||||
getsebool -a | grep -q ^ftp_home_dir && \
|
||||
tcfChk "Return previous state of ftp access rights to home dirs" && {
|
||||
tcfRun "setsebool ftp_home_dir $prevbool_ftp_home_dir" 0 "Return ftp_home_dir boolean back"
|
||||
tcfFin; }
|
||||
tcfChk "Remove ftp user" && {
|
||||
tcfRun "userdel -r ftptest500OOPS" 0 "Remove testing user"
|
||||
tcfFin; }
|
||||
rlServiceRestore vsftpd
|
||||
tcfRun "popd"
|
||||
tcfRun "rm -r $TmpDir" 0 "Removing tmp directory"
|
||||
tcfFin; }
|
||||
}
|
||||
|
||||
rlJournalStart && {
|
||||
rlPhaseStartSetup && {
|
||||
rlImport --all
|
||||
tcfTry "Setup phase" && {
|
||||
for PACKAGE in $PACKAGES; do
|
||||
rlAssertRpm $PACKAGE
|
||||
done
|
||||
for BINARY in $BINARIES; do
|
||||
tcfRun "which $BINARY" 0 "Check presence of $BINARY"
|
||||
done
|
||||
tcfRun "TmpDir=\$(mktemp -d)" 0 "Creating tmp directory"
|
||||
tcfRun "pushd $TmpDir"
|
||||
tcfTry "Setup ftp user" && {
|
||||
tcfRun "useradd ftptest500OOPS" 0 "Create testing user"
|
||||
tcfRun "echo '$PASSWORD' | passwd --stdin ftptest500OOPS"
|
||||
tcfFin; }
|
||||
rlFileBackup --clean /etc/vsftpd/vsftpd.conf
|
||||
tcfTry "setup vsftpd to use data port only 5001-5010" &&{
|
||||
cat >>/etc/vsftpd/vsftpd.conf <<EOF
|
||||
pasv_min_port=5001
|
||||
pasv_max_port=5010
|
||||
EOF
|
||||
tcfFin; }
|
||||
tcfTry "bind to half of ports using nc" &&{
|
||||
for i in `seq 6`; do nc -l 500$i & done
|
||||
tcfFin; }
|
||||
# save/restore boolean state only when it is available
|
||||
getsebool -a | grep -q ^ftp_home_dir && \
|
||||
tcfChk "Allow ftp users to enter home dirs" && {
|
||||
tcfRun "prevbool_ftp_home_dir=$(getsebool ftp_home_dir |sed -e 's/.* --> \(\S\+\).*/\1/')" 0 "Get previous value of ftp_home_dir boolean"
|
||||
tcfE2R
|
||||
tcfRun "setsebool ftp_home_dir 1" 0 "Enable ftp to access home dir"
|
||||
tcfE2R
|
||||
tcfFin; }
|
||||
rlServiceStart vsftpd
|
||||
tcfTry "create testing file" &&{
|
||||
echo "testing file">/home/ftptest500OOPS/testfile
|
||||
tcfFin; }
|
||||
tcfTry "register cleanup trap" &&{
|
||||
trap "clean_up; rlJournalPrintText; rlJournalEnd; exit" SIGHUP SIGINT SIGTERM
|
||||
tcfFin; }
|
||||
tcfFin; }
|
||||
rlPhaseEnd; }
|
||||
|
||||
rlPhaseStartTest && {
|
||||
tcfTry "Test phase" && {
|
||||
tcfTry "do ftp connect and list the directory" &&{
|
||||
expect <<EOF
|
||||
spawn ftp 127.0.0.1
|
||||
set res 0
|
||||
set timeout 10
|
||||
expect {
|
||||
eof { puts "eof"; exit 3}
|
||||
timeout {puts timeout; exit 2}
|
||||
-nocase "name*:" {puts ftptest500OOPS; send -- "ftptest500OOPS\r"}
|
||||
}
|
||||
expect {
|
||||
eof { puts "eof"; exit 3}
|
||||
timeout {puts timeout; exit 2}
|
||||
-nocase "password*:" {puts $PASSWORD; send -- "${PASSWORD}\r"}
|
||||
}
|
||||
for {set i 1} {\$i<=1000} {incr i} {
|
||||
expect {
|
||||
"500 OOPS: vsf_sysutil_bind, maximum number of attempts to find a listening port exceeded" { puts "error found"; set res 0; break}
|
||||
"OOPS" { puts "error found"; set res 5; break}
|
||||
-nocase "not connected" { puts "connection lost"; set res 4; break}
|
||||
eof { puts "eof"; exit 3}
|
||||
timeout {puts timeout; exit 2}
|
||||
-nocase "ftp>" { puts "iteration \$i/1000"; send -- "ls\r"}
|
||||
}
|
||||
}
|
||||
expect {
|
||||
eof { puts "eof"; exit 3}
|
||||
timeout {puts timeout; exit 2}
|
||||
-nocase "ftp>" { send -- "bye\r"}
|
||||
}
|
||||
expect {
|
||||
timeout {puts timeout; exit 2}
|
||||
eof
|
||||
}
|
||||
exit \$res
|
||||
EOF
|
||||
tcfFin; }
|
||||
#PS1="[test] " bash
|
||||
tcfFin; }
|
||||
rlPhaseEnd; }
|
||||
|
||||
rlPhaseStartCleanup && {
|
||||
clean_up
|
||||
tcfCheckFinal
|
||||
rlPhaseEnd; }
|
||||
|
||||
rlJournalPrintText
|
||||
rlJournalEnd; }
|
||||
|
|
@ -1,30 +0,0 @@
|
|||
summary: Test for BZ#2069733 (vsftpd does not support TLSv1.3 cipher suites)
|
||||
description: |
|
||||
Bug summary: Not-able-to-specify-TLS1.3-ciphersuites-in-vsftpd-configuration
|
||||
Bugzilla link: https://bugzilla.redhat.com/show_bug.cgi?id=2069733
|
||||
Test for BZ#2069733 (vsftpd does not support TLSv1.3 cipher suites)
|
||||
component:
|
||||
- vsftpd
|
||||
test: ./runtest.sh
|
||||
framework: beakerlib
|
||||
recommend:
|
||||
- curl
|
||||
- nss
|
||||
- openssl
|
||||
- vsftpd
|
||||
duration: 35m
|
||||
enabled: true
|
||||
tier: '1'
|
||||
link:
|
||||
- verifies: https://bugzilla.redhat.com/show_bug.cgi?id=2069733
|
||||
adjust:
|
||||
- enabled: false
|
||||
when: distro < rhel-8.9
|
||||
continue: false
|
||||
tag:
|
||||
- NoRHEL6
|
||||
- NoRHEL7
|
||||
- Tier1
|
||||
extra-nitrate: TC#0615139
|
||||
id: 66b4240e-acf1-4ac9-902b-f74028bb56ec
|
||||
author: Richard Lescak <rlescak@redhat.com>
|
||||
|
|
@ -1,298 +0,0 @@
|
|||
#!/bin/bash
|
||||
|
||||
lsb_release -r | grep -E '\<5[.]' && FORMAT="+%y%m%d%H%M%SZ" || FORMAT="+%Y%m%d%H%M%SZ"
|
||||
|
||||
set -e
|
||||
|
||||
_DIR="certs"
|
||||
_RSA_CA_CNF_FILE="${_DIR}/ca.cnf"
|
||||
_RSA_SERVER_CNF_FILE="${_DIR}/rsa-server.cnf"
|
||||
_CLIENT_CNF_FILE="${_DIR}/client1.cnf"
|
||||
_CLIENT2_CNF_FILE="${_DIR}/client2.cnf"
|
||||
_INDEX_FILE="${_DIR}/rsa-index.txt"
|
||||
_INDEX2_FILE="${_DIR}/ec-index.txt"
|
||||
_SERIAL_FILE="${_DIR}/rsa-serial"
|
||||
_SERIAL2_FILE="${_DIR}/ec-serial"
|
||||
_RAND_FILE="${_DIR}/rand"
|
||||
_COUNTRY="CZ"
|
||||
_STATE="Czech Republic"
|
||||
_CITY="Brno"
|
||||
_ORG_NAME="TestRedHat"
|
||||
_RSA_CA_COMMON_NAME="CA"
|
||||
_RSA_CA_KEY_FILE="${_DIR}/ca_key.pem"
|
||||
_RSA_CA_BINARY_KEY_FILE="${_DIR}/ca_key.key"
|
||||
_RSA_CA_REQUEST_FILE="${_DIR}/ca_cert.csr"
|
||||
_RSA_CA_CERT_FILE="${_DIR}/ca_cert.pem"
|
||||
_RSA_CA_CRL_FILE="${_DIR}/ca_cert.crl"
|
||||
_RSA_CA_PASSWORD="RedHatEnterpriseLinux"
|
||||
_RSA_CA_EMAIL="ca@test-redhat.example.com"
|
||||
_RSA_SERVER_COMMON_NAME="localhost"
|
||||
_RSA_SERVER_KEY_FILE="${_DIR}/rsa_server_key.pem"
|
||||
_RSA_SERVER_BINARY_KEY_FILE="${_DIR}/rsa_server_key.key"
|
||||
_RSA_SERVER_CERT_FILE="${_DIR}/rsa_server_cert.pem"
|
||||
_RSA_SERVER_REQUEST_FILE="${_DIR}/rsa_server_cert.csr"
|
||||
_RSA_SERVER_P12_FILE="${_DIR}/rsa_server.p12"
|
||||
_RSA_SERVER_KEYCERT_FILE="${_DIR}/rsa_server.pem"
|
||||
_RSA_SERVER_PASSWORD="${_RSA_CA_PASSWORD}"
|
||||
_RSA_SERVER_EMAIL="server@test-redhat.example.com"
|
||||
_CLIENT_COMMON_NAME="client1"
|
||||
_CLIENT_KEY_FILE="${_DIR}/client1_key.pem"
|
||||
_CLIENT_BINARY_KEY_FILE="${_DIR}/client1_key.key"
|
||||
_CLIENT_CERT_FILE="${_DIR}/client1_cert.pem"
|
||||
_CLIENT_REQUEST_FILE="${_DIR}/client1_cert.csr"
|
||||
_CLIENT_P12_FILE="${_DIR}/client1.p12"
|
||||
_CLIENT_KEYCERT_FILE="${_DIR}/client1.pem"
|
||||
_CLIENT_PASSWORD="${_RSA_CA_PASSWORD}"
|
||||
_CLIENT_EMAIL="client@test-redhat.example.com"
|
||||
_ID="01"
|
||||
|
||||
|
||||
function _config() {
|
||||
[ -d ${_DIR} ] && rm -rf ${_DIR}
|
||||
mkdir -p ${_DIR}/crl
|
||||
date_now=`date '+%s'`
|
||||
start_date=`date -d @"$(($date_now - 60*60*24* 365 * 5))" -u "$FORMAT"`
|
||||
end_date=`date -d @"$(($date_now + 60*60*24* 365 * 5))" -u "$FORMAT"`
|
||||
cat <<EOF >${_RSA_CA_CNF_FILE}
|
||||
[ ca ]
|
||||
default_ca = CA_default
|
||||
|
||||
[ CA_default ]
|
||||
dir = ${_DIR}
|
||||
certs = ${_DIR}
|
||||
crl_dir = ${_DIR}/crl
|
||||
database = ${_INDEX_FILE}
|
||||
new_certs_dir = ${_DIR}
|
||||
certificate = ${_RSA_CA_CERT_FILE}
|
||||
serial = ${_SERIAL_FILE}
|
||||
crl = ${_RSA_CA_CRL_FILE}
|
||||
private_key = ${_RSA_CA_KEY_FILE}
|
||||
RANDFILE = ${_RAND_FILE}
|
||||
name_opt = ca_default
|
||||
cert_opt = ca_default
|
||||
default_startdate = ${start_date}
|
||||
default_enddate = ${end_date}
|
||||
default_crl_days = 30
|
||||
default_md = sha256
|
||||
preserve = no
|
||||
policy = policy_match
|
||||
|
||||
[ policy_match ]
|
||||
countryName = match
|
||||
stateOrProvinceName = match
|
||||
organizationName = match
|
||||
localityName = optional
|
||||
organizationalUnitName = optional
|
||||
commonName = supplied
|
||||
emailAddress = optional
|
||||
subjectAltName = optional
|
||||
|
||||
[ policy_anything ]
|
||||
countryName = optional
|
||||
stateOrProvinceName = optional
|
||||
localityName = supplied
|
||||
organizationName = optional
|
||||
organizationalUnitName = optional
|
||||
commonName = supplied
|
||||
emailAddress = optional
|
||||
subjectAltName = optional
|
||||
|
||||
[ req ]
|
||||
prompt = no
|
||||
distinguished_name = certificate_authority
|
||||
default_bits = 2048
|
||||
input_password = ${_RSA_CA_PASSWORD}
|
||||
output_password = ${_RSA_CA_PASSWORD}
|
||||
x509_extensions = v3_ca
|
||||
|
||||
[certificate_authority]
|
||||
countryName = ${_COUNTRY}
|
||||
stateOrProvinceName = ${_STATE}
|
||||
#localityName = ${_CITY}
|
||||
organizationName = ${_ORG_NAME}
|
||||
#emailAddress = ${_RSA_CA_EMAIL}
|
||||
commonName = "${_RSA_CA_COMMON_NAME}"
|
||||
|
||||
[v3_ca]
|
||||
subjectKeyIdentifier = hash
|
||||
authorityKeyIdentifier = keyid:always,issuer:always
|
||||
basicConstraints = CA:true
|
||||
EOF
|
||||
|
||||
start_date=`date -d @"$(($date_now - 60*60*24* 30 * 4))" -u "$FORMAT"`
|
||||
end_date=`date -d @"$(($date_now + 60*60*24* 40 * 8))" -u "$FORMAT"`
|
||||
cat <<EOF >${_RSA_SERVER_CNF_FILE}
|
||||
[ ca ]
|
||||
default_ca = CA_default
|
||||
|
||||
[ CA_default ]
|
||||
dir = ${_DIR}
|
||||
certs = ${_DIR}
|
||||
crl_dir = ${_DIR}/crl
|
||||
database = ${_INDEX_FILE}
|
||||
new_certs_dir = ${_DIR}
|
||||
certificate = ${_RSA_SERVER_CERT_FILE}
|
||||
serial = ${_SERIAL_FILE}
|
||||
crl = ${_RSA_CA_CRL_FILE}
|
||||
private_key = ${_RSA_SERVER_KEY_FILE}
|
||||
RANDFILE = ${_RAND_FILE}
|
||||
name_opt = ca_default
|
||||
cert_opt = ca_default
|
||||
default_startdate = ${start_date}
|
||||
default_enddate = ${end_date}
|
||||
default_crl_days = 30
|
||||
default_md = sha256
|
||||
preserve = no
|
||||
policy = policy_match
|
||||
|
||||
[ policy_match ]
|
||||
countryName = match
|
||||
stateOrProvinceName = match
|
||||
organizationName = match
|
||||
organizationalUnitName = optional
|
||||
commonName = supplied
|
||||
emailAddress = optional
|
||||
subjectAltName = optional
|
||||
|
||||
[ policy_anything ]
|
||||
countryName = optional
|
||||
stateOrProvinceName = optional
|
||||
localityName = optional
|
||||
organizationName = optional
|
||||
organizationalUnitName = optional
|
||||
commonName = supplied
|
||||
emailAddress = optional
|
||||
subjectAltName = optional
|
||||
|
||||
[ req ]
|
||||
prompt = no
|
||||
distinguished_name = client
|
||||
default_bits = 2048
|
||||
input_password = ${_RSA_SERVER_PASSWORD}
|
||||
output_password = ${_RSA_SERVER_PASSWORD}
|
||||
|
||||
[client]
|
||||
countryName = ${_COUNTRY}
|
||||
stateOrProvinceName = ${_STATE}
|
||||
localityName = ${_CITY}
|
||||
organizationName = ${_ORG_NAME}
|
||||
emailAddress = ${_RSA_SERVER_EMAIL}
|
||||
commonName = "${_RSA_SERVER_COMMON_NAME}"
|
||||
|
||||
[v3_ee]
|
||||
basicConstraints =critical, CA:FALSE
|
||||
keyUsage =critical, digitalSignature, keyEncipherment, dataEncipherment, keyAgreement
|
||||
subjectKeyIdentifier=hash
|
||||
authorityKeyIdentifier=keyid:always,issuer
|
||||
extendedKeyUsage=serverAuth
|
||||
subjectAltName = @alt_name
|
||||
|
||||
[alt_name]
|
||||
DNS.1=localhost
|
||||
DNS.2=localhost4
|
||||
DNS.3=localhost6
|
||||
|
||||
EOF
|
||||
|
||||
start_date=`date -d @"$(($date_now - 60*60*24* 30 * 16))" -u "$FORMAT"`
|
||||
end_date=`date -d @"$(($date_now + 60*60*24* 40 * 4))" -u "$FORMAT"`
|
||||
cat <<EOF >${_CLIENT_CNF_FILE}
|
||||
[ ca ]
|
||||
default_ca = CA_default
|
||||
|
||||
[ CA_default ]
|
||||
dir = ${_DIR}
|
||||
certs = ${_DIR}
|
||||
crl_dir = ${_DIR}/crl
|
||||
database = ${_INDEX_FILE}
|
||||
new_certs_dir = ${_DIR}
|
||||
certificate = ${_CLIENT_CERT_FILE}
|
||||
serial = ${_SERIAL_FILE}
|
||||
crl = ${_RSA_CA_CRL_FILE}
|
||||
private_key = ${_CLIENT_KEY_FILE}
|
||||
RANDFILE = ${_RAND_FILE}
|
||||
name_opt = ca_default
|
||||
cert_opt = ca_default
|
||||
default_startdate = ${start_date}
|
||||
default_enddate = ${end_date}
|
||||
default_crl_days = 30
|
||||
default_md = sha256
|
||||
preserve = no
|
||||
policy = policy_match
|
||||
|
||||
[ policy_match ]
|
||||
countryName = match
|
||||
stateOrProvinceName = match
|
||||
organizationName = match
|
||||
organizationalUnitName = optional
|
||||
commonName = supplied
|
||||
emailAddress = optional
|
||||
subjectAltName = optional
|
||||
|
||||
[ policy_anything ]
|
||||
countryName = optional
|
||||
stateOrProvinceName = optional
|
||||
localityName = optional
|
||||
organizationName = optional
|
||||
organizationalUnitName = optional
|
||||
commonName = supplied
|
||||
emailAddress = optional
|
||||
subjectAltName = optional
|
||||
|
||||
[ req ]
|
||||
prompt = no
|
||||
distinguished_name = client
|
||||
default_bits = 2048
|
||||
input_password = ${_CLIENT_PASSWORD}
|
||||
output_password = ${_CLIENT_PASSWORD}
|
||||
|
||||
[client]
|
||||
countryName = ${_COUNTRY}
|
||||
stateOrProvinceName = ${_STATE}
|
||||
localityName = ${_CITY}
|
||||
organizationName = ${_ORG_NAME}
|
||||
emailAddress = ${_CLIENT_EMAIL}
|
||||
commonName = "${_CLIENT_COMMON_NAME}"
|
||||
|
||||
[v3_ee]
|
||||
basicConstraints =critical, CA:FALSE
|
||||
keyUsage =critical, digitalSignature, keyEncipherment, dataEncipherment, keyAgreement
|
||||
subjectKeyIdentifier=hash
|
||||
authorityKeyIdentifier=keyid:always,issuer
|
||||
extendedKeyUsage=clientAuth
|
||||
|
||||
EOF
|
||||
echo "${_ID}" >${_SERIAL_FILE}
|
||||
touch ${_INDEX_FILE}
|
||||
echo "${_ID}" >${_SERIAL2_FILE}
|
||||
touch ${_INDEX2_FILE}
|
||||
}
|
||||
|
||||
|
||||
_config
|
||||
|
||||
# RSA CA
|
||||
# Because we can't specify starttime and endtime when generating self signed
|
||||
# certificate, we need to sign/create CA certificate twice
|
||||
openssl req -x509 -newkey rsa:2048 -set_serial 1 -keyout ${_RSA_CA_KEY_FILE} -out ${_RSA_CA_CERT_FILE} -config ${_RSA_CA_CNF_FILE}
|
||||
openssl x509 -x509toreq -signkey ${_RSA_CA_KEY_FILE} -out ${_RSA_CA_REQUEST_FILE} -in ${_RSA_CA_CERT_FILE} -passin pass:${_RSA_CA_PASSWORD}
|
||||
openssl ca -batch -keyfile ${_RSA_CA_KEY_FILE} -cert ${_RSA_CA_CERT_FILE} -in ${_RSA_CA_REQUEST_FILE} -key ${_RSA_CA_PASSWORD} -out ${_RSA_CA_CERT_FILE} -extensions v3_ca -config ${_RSA_CA_CNF_FILE}
|
||||
openssl rsa -in ${_RSA_CA_KEY_FILE} -out ${_RSA_CA_BINARY_KEY_FILE} -passin pass:${_RSA_CA_PASSWORD}
|
||||
openssl x509 -in ${_RSA_CA_CERT_FILE} -noout -text
|
||||
|
||||
# RSA server
|
||||
openssl req -newkey rsa:2048 -keyout ${_RSA_SERVER_KEY_FILE} -out ${_RSA_SERVER_REQUEST_FILE} -config ${_RSA_SERVER_CNF_FILE}
|
||||
openssl ca -batch -keyfile ${_RSA_CA_KEY_FILE} -cert ${_RSA_CA_CERT_FILE} -in ${_RSA_SERVER_REQUEST_FILE} -key ${_RSA_CA_PASSWORD} -out ${_RSA_SERVER_CERT_FILE} -extensions v3_ee -config ${_RSA_SERVER_CNF_FILE}
|
||||
openssl rsa -in ${_RSA_SERVER_KEY_FILE} -out ${_RSA_SERVER_BINARY_KEY_FILE} -passin pass:${_RSA_SERVER_PASSWORD}
|
||||
openssl pkcs12 -export -in ${_RSA_SERVER_CERT_FILE} -inkey ${_RSA_SERVER_KEY_FILE} -out ${_RSA_SERVER_P12_FILE} -passin pass:${_RSA_SERVER_PASSWORD} -passout pass:${_RSA_SERVER_PASSWORD}
|
||||
cat ${_RSA_SERVER_KEY_FILE} ${_RSA_SERVER_CERT_FILE} >${_RSA_SERVER_KEYCERT_FILE}
|
||||
cp ${_RSA_SERVER_KEYCERT_FILE} ${_RSA_SERVER_P12_FILE} .
|
||||
|
||||
# client1 certificate
|
||||
openssl req -newkey rsa:2048 -keyout ${_CLIENT_KEY_FILE} -out ${_CLIENT_REQUEST_FILE} -config ${_CLIENT_CNF_FILE}
|
||||
openssl ca -batch -keyfile ${_RSA_CA_KEY_FILE} -cert ${_RSA_CA_CERT_FILE} -in ${_CLIENT_REQUEST_FILE} -key ${_RSA_CA_PASSWORD} -out ${_CLIENT_CERT_FILE} -extensions v3_ee -config ${_CLIENT_CNF_FILE}
|
||||
openssl rsa -in ${_CLIENT_KEY_FILE} -out ${_CLIENT_BINARY_KEY_FILE} -passin pass:${_CLIENT_PASSWORD}
|
||||
openssl pkcs12 -export -in ${_CLIENT_CERT_FILE} -inkey ${_CLIENT_KEY_FILE} -out ${_CLIENT_P12_FILE} -passin pass:${_CLIENT_PASSWORD} -passout pass:${_CLIENT_PASSWORD}
|
||||
cat ${_CLIENT_BINARY_KEY_FILE} ${_CLIENT_CERT_FILE} >${_CLIENT_KEYCERT_FILE}
|
||||
cp ${_CLIENT_KEYCERT_FILE} ${_CLIENT_P12_FILE} .
|
||||
|
||||
|
|
@ -1,93 +0,0 @@
|
|||
#!/bin/bash
|
||||
# vim: dict=/usr/share/beakerlib/dictionary.vim cpt=.,w,b,u,t,i,k
|
||||
# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||
#
|
||||
# runtest.sh of /CoreOS/vsftpd/Sanity/bz2069733-Not-able-to-specify-TLS1.3-ciphersuites-in-vsftpd-configuration
|
||||
# Description: Test for BZ#2069733 (Not able to specify TLSv1.3 ciphersuites for vsftpd)
|
||||
# Author: Richard Lescak <rlescak@redhat.com>
|
||||
#
|
||||
# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||
#
|
||||
# Copyright (c) 2023 Red Hat, Inc.
|
||||
#
|
||||
# This copyrighted material is made available to anyone wishing
|
||||
# to use, modify, copy, or redistribute it subject to the terms
|
||||
# and conditions of the GNU General Public License version 2.
|
||||
#
|
||||
# This program is distributed in the hope that it will be
|
||||
# useful, but WITHOUT ANY WARRANTY; without even the implied
|
||||
# warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR
|
||||
# PURPOSE. See the GNU General Public License for more details.
|
||||
#
|
||||
# You should have received a copy of the GNU General Public
|
||||
# License along with this program; if not, write to the Free
|
||||
# Software Foundation, Inc., 51 Franklin Street, Fifth Floor,
|
||||
# Boston, MA 02110-1301, USA.
|
||||
#
|
||||
# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||
|
||||
# Include Beaker environment
|
||||
. /usr/share/beakerlib/beakerlib.sh || exit 1
|
||||
|
||||
PACKAGE="vsftpd"
|
||||
PACKAGES="nss curl openssl vsftpd"
|
||||
VSFTPDCONF="/etc/vsftpd/vsftpd.conf"
|
||||
|
||||
rlJournalStart
|
||||
rlPhaseStartSetup
|
||||
rlAssertRpm --all
|
||||
rlRun "TmpDir=\$(mktemp -d)" 0 "Creating tmp directory"
|
||||
TMP_CA_CERT=$TmpDir/certs/ca_cert.pem
|
||||
TMP_SERVER_CERT=$TmpDir/certs/rsa_server_cert.pem
|
||||
TMP_SERVER_KEY=$TmpDir/certs/rsa_server_key.key
|
||||
CLIENT_CERT=$TmpDir/certs/client1_cert.pem
|
||||
CLIENT_KEY=$TmpDir/certs/client1_key.key
|
||||
CA_CERT=/etc/pki/CA/certs/ca_cert.pem
|
||||
SERVER_CERT=/etc/pki/tls/certs/rsa_server_cert.pem
|
||||
SERVER_KEY=/etc/pki/tls/private/rsa_server_key.key
|
||||
CLIENT_PASS="RedHatEnterpriseLinux"
|
||||
rlRun "cp make_certs.sh $TmpDir" 0 "Copy cert creation script to tmp dir"
|
||||
rlRun "pushd $TmpDir"
|
||||
rlRun "./make_certs.sh" 0 "Create server and user certificates"
|
||||
rlFileBackup $VSFTPDCONF
|
||||
rlRun "sed -i 's/anonymous_enable=NO/anonymous_enable=YES/' /etc/vsftpd/vsftpd.conf"
|
||||
rlRun "mkdir -p /etc/pki/CA/certs/ /etc/pki/tls/certs/ /etc/pki/tls/private/" 0 "Create dirs for certificates"
|
||||
rlRun "cp $TMP_CA_CERT $CA_CERT" 0 "Copy CA cert to system dir"
|
||||
rlRun "cp $TMP_SERVER_CERT $SERVER_CERT" 0 "Copy server cert to system dir"
|
||||
rlRun "cp $TMP_SERVER_KEY $SERVER_KEY" 0 "Copy server key to system dir"
|
||||
rlRun "sed -i 's/^ssl_enable.*//' $VSFTPDCONF" 0 "Remove ssl_enable directives"
|
||||
rlRun "echo 'ssl_enable=YES' >> $VSFTPDCONF" 0 "Add ssl_enable=yes config option"
|
||||
rlRun "sed -i 's/^ssl_ciphersuites.*//' $VSFTPDCONF" 0 "Remove ssl_ciphers directives"
|
||||
|
||||
rlRun "echo 'ssl_ciphersuites=TLS_AES_256_GCM_SHA384' >> $VSFTPDCONF" 0 "Add ssl_ciphersuites=TLS_AES_256_GCM_SHA384 config option"
|
||||
|
||||
rlRun "sed -i 's/^allow_anon_ssl.*//' $VSFTPDCONF" 0 "Remove allow_anon_ssl directive"
|
||||
rlRun "echo 'allow_anon_ssl=YES' >> $VSFTPDCONF" 0 "Add allow_anon_ssl=YES config option"
|
||||
rlRun "sed -i 's/^require_ssl_reuse.*//' $VSFTPDCONF" 0 "Remove require_ssl_reuse directive"
|
||||
rlRun "echo 'require_ssl_reuse=NO' >> $VSFTPDCONF" 0 "Set require_ssl_reuse=NO config option"
|
||||
rlRun "sed -i 's/^ca_certs_file.*//' $VSFTPDCONF" 0 "Remove ca_certs_file directive"
|
||||
rlRun "echo 'ca_certs_file=$CA_CERT' >> $VSFTPDCONF" 0 "Set ca_certs_file=$CA_CERT config option"
|
||||
rlRun "sed -i 's/^rsa_cert_file.*//' $VSFTPDCONF" 0 "Remove rsa_cert_file directive"
|
||||
rlRun "echo 'rsa_cert_file=$SERVER_CERT' >> $VSFTPDCONF" 0 "Set rsa_cert_file=$SERVER_CERT option"
|
||||
rlRun "sed -i 's/^rsa_private_key_file.*//' $VSFTPDCONF" 0 "Remove rsa_private_key_file directive"
|
||||
rlRun "echo 'rsa_private_key_file=$SERVER_KEY' >> $VSFTPDCONF" 0 "Set rsa_private_key_file=$SERVER_KEY option"
|
||||
rlRun "echo 'ssl_tlsv1_3=YES' >> $VSFTPDCONF" 0 "Set ssl_tlsv1_3=YES option"
|
||||
rlRun "echo test > /var/ftp/pub/file" 0 "Create test file on FTP"
|
||||
rlServiceStart vsftpd
|
||||
rlPhaseEnd
|
||||
rlPhaseStartTest
|
||||
rlRun -s "curl -vv --tls-max 1.3 --ftp-ssl-reqd -u anonymous: -P lo --cacert $CA_CERT ftp://localhost/pub/file < /dev/null > file" 0 "Download file from FTP server"
|
||||
rlRun "grep TLS_AES_256_GCM_SHA384 $rlRun_LOG" 0 "Check if server negotiated TLSv1.3 based cipher suite"
|
||||
rlRun "grep test file" 0 "Check if contents of downloaded file are correct"
|
||||
rlPhaseEnd
|
||||
|
||||
rlPhaseStartCleanup
|
||||
rlRun "popd"
|
||||
rlRun "rm -r $TmpDir" 0 "Removing tmp directory"
|
||||
rlRun "rm -rf $CA_CERT $SERVER_CERT $SERVER_KEY" 0 "Remove certificates installed in system directories"
|
||||
rlFileRestore
|
||||
rlServiceRestore vsftpd
|
||||
rlPhaseEnd
|
||||
|
||||
rlJournalPrintText
|
||||
rlJournalEnd
|
||||
|
|
@ -1,37 +0,0 @@
|
|||
summary: 'Description: Test intend for testing bugs in erratum. bad asterisks, bad
|
||||
xferlog, bad virtual servers'
|
||||
description: |
|
||||
Update: Ales Marecek <amarecek@redhat.com>
|
||||
'Description
|
||||
component:
|
||||
- vsftpd
|
||||
test: ./runtest.sh
|
||||
framework: beakerlib
|
||||
recommend:
|
||||
- vsftpd
|
||||
- lftp
|
||||
- grep
|
||||
duration: 35m
|
||||
enabled: true
|
||||
tag:
|
||||
- Tier1
|
||||
- notip
|
||||
- rhel-6.3
|
||||
tier: '1'
|
||||
link:
|
||||
- relates: https://bugzilla.redhat.com/show_bug.cgi?id=460069
|
||||
- relates: https://bugzilla.redhat.com/show_bug.cgi?id=465216
|
||||
- relates: https://bugzilla.redhat.com/show_bug.cgi?id=517292
|
||||
- relates: https://bugzilla.redhat.com/show_bug.cgi?id=1000974
|
||||
- relates: https://bugzilla.redhat.com/show_bug.cgi?id=967536
|
||||
- relates: https://bugzilla.redhat.com/show_bug.cgi?id=833073
|
||||
- relates: https://bugzilla.redhat.com/show_bug.cgi?id=701300
|
||||
- relates: https://bugzilla.redhat.com/show_bug.cgi?id=1022066
|
||||
- relates: https://bugzilla.redhat.com/show_bug.cgi?id=860951
|
||||
- relates: https://bugzilla.redhat.com/show_bug.cgi?id=838610
|
||||
- relates: https://bugzilla.redhat.com/show_bug.cgi?id=479774
|
||||
extra-nitrate: TC#0091534
|
||||
extra-summary: /CoreOS/vsftpd/Sanity/bz460069-starts-vsftpd-and-by-lftp-try-bugs
|
||||
extra-task: /CoreOS/vsftpd/Sanity/bz460069-starts-vsftpd-and-by-lftp-try-bugs
|
||||
id: 4b704336-12ba-460d-9e25-4549a8eb674b
|
||||
author: Jan Scotka <jscotka@redhat.com>
|
||||
|
|
@ -1,111 +0,0 @@
|
|||
#!/bin/bash
|
||||
# vim: dict=/usr/share/rhts-library/dictionary.vim cpt=.,w,b,u,t,i,k
|
||||
# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||
#
|
||||
# runtest.sh of /CoreOS/vsftpd/Sanity/bz460069-starts-vsftpd-and-by-lftp-try-bugs
|
||||
# Description: Description: Test intend for testing bugs in erratum. bad asterisks, bad xferlog, bad virtual servers
|
||||
# Author: Jan Scotka <jscotka@redhat.com>
|
||||
# Update: Ales Marecek <amarecek@redhat.com>
|
||||
#
|
||||
# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||
#
|
||||
# Copyright (c) 2009 Red Hat, Inc. All rights reserved.
|
||||
#
|
||||
# This copyrighted material is made available to anyone wishing
|
||||
# to use, modify, copy, or redistribute it subject to the terms
|
||||
# and conditions of the GNU General Public License version 2.
|
||||
#
|
||||
# This program is distributed in the hope that it will be
|
||||
# useful, but WITHOUT ANY WARRANTY; without even the implied
|
||||
# warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR
|
||||
# PURPOSE. See the GNU General Public License for more details.
|
||||
#
|
||||
# You should have received a copy of the GNU General Public
|
||||
# License along with this program; if not, write to the Free
|
||||
# Software Foundation, Inc., 51 Franklin Street, Fifth Floor,
|
||||
# Boston, MA 02110-1301, USA.
|
||||
#
|
||||
# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||
|
||||
# Include rhts environment
|
||||
. /usr/share/beakerlib/beakerlib.sh || exit 1
|
||||
|
||||
PACKAGE="vsftpd"
|
||||
# it is neccessary to have '*' in there because in different versions of RHEL there are 'vsftpd' or 'vsftpd.log' files
|
||||
_LOGROTATE_FILE='/etc/logrotate.d/vsftpd*'
|
||||
|
||||
rlJournalStart
|
||||
rlPhaseStartSetup Setup
|
||||
rlAssertRpm $PACKAGE
|
||||
rlRun "TmpDir=\`mktemp -d\`" 0 "Creating tmp directory"
|
||||
|
||||
FTPDIR=/var/ftp
|
||||
FTP=/etc/vsftpd
|
||||
FTPCONF=$FTP/vsftpd.conf
|
||||
OUTDIR=$TmpDir
|
||||
cd $OUTDIR
|
||||
|
||||
rlRun "rlFileBackup --clean $FTP $FTPDIR /root/.config /root/.local" 0-255
|
||||
if ! rlIsRHEL '<8'; then
|
||||
rlRun "sed -i s/anonymous_enable=NO/anonymous_enable=YES/ $FTPCONF" 0 "Enable anonymous login"
|
||||
# Since rhel8 anonymous login is disabled by default
|
||||
fi
|
||||
rlRun "ip addr add 192.168.0.1/8 dev lo"
|
||||
rlRun "ip addr add 192.168.0.2/8 dev lo"
|
||||
rlRun "ip addr"
|
||||
|
||||
rlAssertExists $FTPDIR
|
||||
rlRun "rm -rf $FTPDIR/* 2>/dev/null"
|
||||
rlRun "cat /dev/null > /var/log/xferlog"
|
||||
rlRun "cat /dev/null > /var/log/vsftpd.log"
|
||||
rlRun "restorecon -Fv /var/log/*"
|
||||
|
||||
# echo xferlog_file=/var/log/vsftpd.log >> $FTPCONF
|
||||
|
||||
rlRun "touch $FTPDIR/abc.file"
|
||||
rlRun "touch $FTPDIR/a_b_c_.file"
|
||||
rlRun "touch $FTPDIR/a_b_c_d.file"
|
||||
rlRun "touch $FTPDIR/a_b_c_d_e.file"
|
||||
rlRun "rlServiceStart vsftpd"
|
||||
rlFileSubmit /etc/vsftpd/vsftpd.conf
|
||||
rlPhaseEnd
|
||||
|
||||
rlPhaseStartTest Testing
|
||||
rlAssertExists $TmpDir
|
||||
rlRun "ls -l $TmpDir" 0 "Listing tmp directory"
|
||||
####### 479774 - ON_QA - [RHEL 4] Wildcard failures with vsftpd
|
||||
rlRun 'lftp `hostname` -e "ls *.file; bye" | tee --append /dev/stderr | wc -l | grep -q 4 ' 0 " pass 4"
|
||||
rlRun 'lftp `hostname` -e "ls *_*.file; bye" | tee --append /dev/stderr | wc -l | grep -q 3 ' 0 " pass 3"
|
||||
rlRun 'lftp `hostname` -e "ls *_*_*.file; bye" | tee --append /dev/stderr | wc -l | grep -q 3 ' 0 " pass 3"
|
||||
rlRun 'lftp `hostname` -e "ls *_*_*_*.file; bye" | tee --append /dev/stderr | wc -l | grep -q 3 ' 0 " pass 3"
|
||||
rlRun 'lftp `hostname` -e "ls *_*_*_*_*.file; bye" | tee --append /dev/stderr | wc -l | grep -q 1 ' 0 " pass 1"
|
||||
rlRun 'lftp `hostname` -e "ls *_*_*_*_*_*.file; bye" | tee --append /dev/stderr | wc -l | grep -q 0 ' 0 " pass 0"
|
||||
|
||||
####### 460069 - ON_QA - RHEL4 vsftpd.conf lists incorrect default value for xferlog_file
|
||||
rlRun 'lftp `hostname` -e "mget *.file; bye"'
|
||||
rlRun '[ -s /var/log/xferlog ]' 0 "PASS /var/log/xferlog "
|
||||
rlRun '[ -s /var/log/vsftpd.log ]' 1-255 "PASS /var/log/vsftpd.log "
|
||||
|
||||
rlLog "${_LOGROTATE_FILE} cointans both vsftpd.log and xferlog items"
|
||||
rlRun "grep -q '/var/log/vsftpd.log' ${_LOGROTATE_FILE} && grep -q '/var/log/xferlog' ${_LOGROTATE_FILE}" 0 "PASS right setup of logrotate"
|
||||
|
||||
####### 465216 - ON_QA - 'binary operator expected' occurs in virtual hosting vsftpd
|
||||
rlRun "cp $FTPCONF $FTP/vsftpd2.conf"
|
||||
rlRun "echo listen_address=192.168.0.1 >> $FTPCONF"
|
||||
rlRun "echo listen_address=192.168.0.2 >> $FTP/vsftpd2.conf"
|
||||
|
||||
rlRun "service vsftpd restart >out 2>err"
|
||||
rlAssertNotGrep "binary operator expected" err
|
||||
rlPhaseEnd
|
||||
|
||||
rlPhaseStartCleanup Cleanup
|
||||
rlRun "ip addr del 192.168.0.2/8 dev lo"
|
||||
rlRun "ip addr del 192.168.0.1/8 dev lo"
|
||||
rlRun "ip addr"
|
||||
|
||||
rlRun "rlFileRestore"
|
||||
rlRun "rlServiceRestore vsftpd"
|
||||
rlRun "rm -r $TmpDir" 0 "Removing tmp directory"
|
||||
rlPhaseEnd
|
||||
rlJournalPrintText
|
||||
rlJournalEnd
|
||||
|
|
@ -1,31 +0,0 @@
|
|||
summary: Test for bz638873 ([RFE] Allow announcement of UTF-8 feature support)
|
||||
description: |
|
||||
Bug summary: [RFE] Allow announcement of UTF-8 feature support as per RFC2640
|
||||
Bugzilla link: https://bugzilla.redhat.com/show_bug.cgi?id=638873
|
||||
Test for bz638873 ([RFE] Allow announcement of UTF-8 feature support)
|
||||
https://bugzilla.redhat.com/show_bug.cgi?id=638873
|
||||
component:
|
||||
- lftp
|
||||
- vsftpd
|
||||
test: ./runtest.sh
|
||||
framework: beakerlib
|
||||
require:
|
||||
- library(distribution/dpcommon)
|
||||
- library(selinux-policy/common)
|
||||
recommend:
|
||||
- lftp
|
||||
- vsftpd
|
||||
duration: 35m
|
||||
enabled: true
|
||||
tag:
|
||||
- TIPfail_Security
|
||||
- TIPfail_infra
|
||||
- TIPpass_Apps
|
||||
- rhel-5.8
|
||||
link:
|
||||
- relates: https://bugzilla.redhat.com/show_bug.cgi?id=638873
|
||||
extra-nitrate: TC#0118691
|
||||
extra-summary: /CoreOS/vsftpd/Sanity/bz638873-RFE-Allow-announcement-of-UTF-8-feature-support
|
||||
extra-task: /CoreOS/vsftpd/Sanity/bz638873-RFE-Allow-announcement-of-UTF-8-feature-support
|
||||
id: 97f95140-2df0-47eb-b5ab-63fde842dadc
|
||||
author: Dalibor Pospisil <dapospis@redhat.com>
|
||||
|
|
@ -1,100 +0,0 @@
|
|||
#!/bin/bash
|
||||
# vim: dict=/usr/share/beakerlib/dictionary.vim cpt=.,w,b,u,t,i,k
|
||||
# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||
#
|
||||
# runtest.sh of /CoreOS/vsftpd/Sanity/bz638873-RFE-Allow-announcement-of-UTF-8-feature-support
|
||||
# Description: Test for bz638873 ([RFE] Allow announcement of UTF-8 feature support)
|
||||
# Author: Dalibor Pospisil <dapospis@redhat.com>
|
||||
#
|
||||
# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||
#
|
||||
# Copyright (c) 2011 Red Hat, Inc. All rights reserved.
|
||||
#
|
||||
# This copyrighted material is made available to anyone wishing
|
||||
# to use, modify, copy, or redistribute it subject to the terms
|
||||
# and conditions of the GNU General Public License version 2.
|
||||
#
|
||||
# This program is distributed in the hope that it will be
|
||||
# useful, but WITHOUT ANY WARRANTY; without even the implied
|
||||
# warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR
|
||||
# PURPOSE. See the GNU General Public License for more details.
|
||||
#
|
||||
# You should have received a copy of the GNU General Public
|
||||
# License along with this program; if not, write to the Free
|
||||
# Software Foundation, Inc., 51 Franklin Street, Fifth Floor,
|
||||
# Boston, MA 02110-1301, USA.
|
||||
#
|
||||
# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||
|
||||
# Include Beaker environment
|
||||
. /usr/share/beakerlib/beakerlib.sh || exit 1
|
||||
|
||||
PACKAGE="vsftpd"
|
||||
|
||||
rlJournalStart
|
||||
rlPhaseStartSetup
|
||||
rlRun "rlImport --all" 0 "Import libraries" || rlDie "cannot continue"
|
||||
tcfTry "Setup phase" && {
|
||||
rlAssertRpm $PACKAGE; tcfE2R
|
||||
tcfRun "TmpDir=\$(mktemp -d)" 0 "Creating tmp directory"; tcfE2R
|
||||
tcfRun "pushd $TmpDir"; tcfE2R
|
||||
|
||||
tcfChk "Allow ftp users to enter home dirs" && {
|
||||
tcfRun "rlSEBooleanBackup"
|
||||
tcfRun "rlSEBooleanOn ftp_home_dir || rlSEBooleanOn ftpd_full_access" 0 "Either allow ftp_home_dir or ftpd_full_access"
|
||||
#tcfRun "prevbool_ftp_home_dir=$(getsebool ftp_home_dir |sed -e 's/.* --> \(\S\+\).*/\1/')" 0 "Get previous value of ftp_home_dir boolean"
|
||||
#tcfE2R
|
||||
#tcfRun "setsebool ftp_home_dir 1" 0 "Enable ftp to access home dir"
|
||||
#tcfE2R
|
||||
tcfFin; }
|
||||
|
||||
tcfTry "Setup ftp user" && {
|
||||
tcfRun "useradd ftptest638873" 0 "Create testing user"
|
||||
tcfRun "echo 'T4jn3h3s10' | passwd --stdin ftptest638873"
|
||||
tcfFin; }
|
||||
|
||||
tcfTry "Start vsftpd service" && {
|
||||
rlServiceStart vsftpd
|
||||
tcfFin; }
|
||||
tcfFin; }
|
||||
rlPhaseEnd
|
||||
|
||||
rlPhaseStartTest
|
||||
tcfTry "Test phase" && {
|
||||
tcfTry "lftp -d ftptest638873:T4jn3h3s10@127.0.0.1" && {
|
||||
expect <<EOF
|
||||
spawn -noecho lftp -d ftptest638873:T4jn3h3s10@127.0.0.1
|
||||
send -- "ls\rbye\r"
|
||||
set timeout 2
|
||||
expect {
|
||||
"UTF8" {exit 0}
|
||||
timeout {exit 1 }
|
||||
eof {exit 1}
|
||||
}
|
||||
EOF
|
||||
tcfFin; }
|
||||
tcfFin; }
|
||||
rlPhaseEnd
|
||||
|
||||
rlPhaseStartCleanup
|
||||
tcfChk "Cleanup phase" && {
|
||||
tcfChk "Return vsftpd service to previous state" && {
|
||||
rlServiceRestore vsftpd
|
||||
tcfFin; }
|
||||
tcfChk "Remove ftp user" && {
|
||||
tcfRun "userdel -r ftptest638873" 0 "Remove testing user"
|
||||
tcfFin; }
|
||||
tcfChk "Return previous state of ftp access rights to home dirs" && {
|
||||
tcfRun "rlSEBooleanRestore"
|
||||
#tcfRun "setsebool ftp_home_dir $prevbool_ftp_home_dir" 0 "Return ftp_home_dir boolean back"
|
||||
tcfFin; }
|
||||
|
||||
tcfRun "popd"; tcfE2R
|
||||
tcfRun "rm -r $TmpDir" 0 "Removing tmp directory"; tcfE2R
|
||||
tcfRun "rm -rf ~/.config ~/.local ~/.lftp"; tcfE2R
|
||||
tcfFin; }
|
||||
tcfCheckFinal
|
||||
rlPhaseEnd
|
||||
rlJournalPrintText
|
||||
rlJournalEnd
|
||||
|
||||
|
|
@ -1,12 +0,0 @@
|
|||
# Test
|
||||
|
||||
## Step
|
||||
1 start vsftpd service
|
||||
|
||||
2 connect by lftp client with '-d' option
|
||||
|
||||
3 execute any command (ls)
|
||||
|
||||
## Expect
|
||||
3 check that feature list includes UTF8 item
|
||||
|
||||
|
|
@ -1,36 +0,0 @@
|
|||
summary: Test of basic functionality related to userlist options.
|
||||
description: |
|
||||
Test of basic functionality related to userlist options.
|
||||
component:
|
||||
- vsftpd
|
||||
test: ./runtest.sh
|
||||
framework: beakerlib
|
||||
require:
|
||||
- library(distribution/Cleanup)
|
||||
- library(distribution/testUser)
|
||||
- library(selinux-policy/common)
|
||||
recommend:
|
||||
- vsftpd
|
||||
- ftp
|
||||
duration: 35m
|
||||
enabled: true
|
||||
tag:
|
||||
- NoRHEL4
|
||||
- TIP_fedora_fail
|
||||
- TIPfail_infra
|
||||
- TIPfail_samba
|
||||
- TIPfail_systemd
|
||||
- TIPpass
|
||||
- TIPpass_FIPS
|
||||
- TIPpass_Security
|
||||
- Tier1
|
||||
tier: '1'
|
||||
adjust:
|
||||
- enabled: false
|
||||
when: distro == rhel-4
|
||||
continue: false
|
||||
extra-nitrate: TC#0484322
|
||||
extra-summary: /CoreOS/vsftpd/Sanity/userlist
|
||||
extra-task: /CoreOS/vsftpd/Sanity/userlist
|
||||
id: 16064b68-c91d-4205-8f00-87b58a8d17fc
|
||||
author: Marek Haicman <mhaicman@redhat.com>
|
||||
|
|
@ -1,235 +0,0 @@
|
|||
#!/bin/bash
|
||||
# vim: dict+=/usr/share/beakerlib/dictionary.vim cpt=.,w,b,u,t,i,k expandtab
|
||||
# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||
#
|
||||
# runtest.sh of /CoreOS/vsftpd/Sanity/userlist
|
||||
# Description: Test of basic functionality related to userlist options.
|
||||
# Author: Marek Haicman <mhaicman@redhat.com>
|
||||
#
|
||||
# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||
#
|
||||
# Copyright (c) 2015 Red Hat, Inc.
|
||||
#
|
||||
# This program is free software: you can redistribute it and/or
|
||||
# modify it under the terms of the GNU General Public License as
|
||||
# published by the Free Software Foundation, either version 2 of
|
||||
# the License, or (at your option) any later version.
|
||||
#
|
||||
# This program is distributed in the hope that it will be
|
||||
# useful, but WITHOUT ANY WARRANTY; without even the implied
|
||||
# warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR
|
||||
# PURPOSE. See the GNU General Public License for more details.
|
||||
#
|
||||
# You should have received a copy of the GNU General Public License
|
||||
# along with this program. If not, see http://www.gnu.org/licenses/.
|
||||
#
|
||||
# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||
|
||||
# Include Beaker environment
|
||||
. /usr/share/beakerlib/beakerlib.sh || exit 1
|
||||
|
||||
PACKAGE="vsftpd"
|
||||
_SERVICE=${PACKAGE}
|
||||
_CONFIG="/etc/vsftpd/vsftpd.conf"
|
||||
_ERRORS=0
|
||||
_WORK_DIR=""
|
||||
_LOG_FILE="vsftpd.log"
|
||||
_TEMP_LOG_FILE="vsftpd.temp.log"
|
||||
_FTP_SERVER="127.0.0.1"
|
||||
_DEFAULT_USERLIST="/etc/vsftpd/user_list"
|
||||
_DEFINED_USERLIST="/etc/vsftpd/user_list_defined"
|
||||
_DEFAULT_DUAL_LOG="/var/log/vsftpd_nondefault.log"
|
||||
|
||||
function _make_config() {
|
||||
if rlIsRHEL '<=7'; then
|
||||
TCP="YES"
|
||||
else
|
||||
# Since 3.0.3-16 in rhel8 tcp wrappers are not compiled in vsftpd
|
||||
TCP="NO"
|
||||
fi
|
||||
cat << EOF >${_CONFIG}
|
||||
anonymous_enable=NO
|
||||
local_enable=YES
|
||||
local_umask=022
|
||||
xferlog_enable=YES
|
||||
xferlog_std_format=YES
|
||||
userlist_enable=YES
|
||||
listen=YES
|
||||
tcp_wrappers=${TCP}
|
||||
connect_from_port_20=YES
|
||||
pam_service_name=vsftpd
|
||||
dual_log_enable=YES
|
||||
vsftpd_log_file=${_DEFAULT_DUAL_LOG}
|
||||
EOF
|
||||
for option in $@; do
|
||||
echo "$option" >> ${_CONFIG}
|
||||
done
|
||||
rlRun "rlServiceStart ${_SERVICE}"
|
||||
}
|
||||
|
||||
|
||||
|
||||
function _checkLogin() {
|
||||
local EXPECTING=${1:-"Pass"}
|
||||
cat ${_TEMP_LOG_FILE} >> ${_LOG_FILE}
|
||||
|
||||
if [[ "${EXPECTING}" == "Pass" ]]; then
|
||||
# Success is expected
|
||||
if [ "`grep '230 Login successful.' ${_TEMP_LOG_FILE}`" ]; then
|
||||
rlPass "Login successful"
|
||||
else
|
||||
_ERRORS=`expr ${_ERRORS} + 1`
|
||||
rlFail "Login failed"
|
||||
fi
|
||||
else
|
||||
# Failure is expected
|
||||
if [ "`grep '230 Login successful.' ${_TEMP_LOG_FILE}`" ]; then
|
||||
_ERRORS=`expr ${_ERRORS} + 1`
|
||||
rlFail "Login successful"
|
||||
else
|
||||
rlPass "Login failed"
|
||||
fi
|
||||
fi
|
||||
}
|
||||
|
||||
function _connect() {
|
||||
# connects as {1} user with {2} passwd
|
||||
ftp -vind <<EOF >${_TEMP_LOG_FILE} 2>&1
|
||||
open ${_FTP_SERVER}
|
||||
quote user ${1}
|
||||
quote pass ${2}
|
||||
quit
|
||||
EOF
|
||||
}
|
||||
|
||||
rlJournalStart
|
||||
rlPhaseStartSetup
|
||||
rlRun "rlImport --all" 0 "Import libraries" || rlDie "cannot continue"
|
||||
rlAssertRpm $PACKAGE
|
||||
|
||||
CleanupRegister "sysctl $(sysctl -e net.ipv6.bindv6only | tr -d ' ')"
|
||||
|
||||
rlRun "TmpDir=\`mktemp -d\`" 0 "Creating tmp directory"
|
||||
rlRun "pushd $TmpDir"
|
||||
CleanupRegister "rlRun 'rm -r $TmpDir' 0 'Removing tmp directory'"
|
||||
CleanupRegister "rlRun 'popd'"
|
||||
_WORK_DIR=${TmpDir}
|
||||
_LOG_FILE="${_WORK_DIR}/${_LOG_FILE}"
|
||||
rlFileBackup --clean ${_CONFIG}
|
||||
CleanupRegister "rlRun 'rlFileRestore'"
|
||||
rlServiceStop ${_SERVICE}
|
||||
CleanupRegister "rlServiceRestore ${_SERVICE}"
|
||||
|
||||
rlRun "rlSEBooleanOn ftpd_full_access"
|
||||
CleanupRegister "rlRun 'rlSEBooleanRestore'"
|
||||
|
||||
rlFileBackup --clean ${_DEFAULT_DUAL_LOG}
|
||||
|
||||
# test user creation
|
||||
rlRun "testUserSetup 6"
|
||||
CleanupRegister "testUserCleanup"
|
||||
|
||||
# filling userlists (first five to default, rest to defined)
|
||||
rlFileBackup --clean ${_DEFAULT_USERLIST}
|
||||
rlFileBackup --clean ${_DEFINED_USERLIST}
|
||||
echo "" > ${_DEFAULT_USERLIST}
|
||||
echo "" > ${_DEFINED_USERLIST}
|
||||
for index in $(seq 0 2); do
|
||||
rlRun "echo ${testUser[$index]} >> ${_DEFAULT_USERLIST}"
|
||||
done
|
||||
for index in $(seq 3 5); do
|
||||
rlRun "echo ${testUser[$index]} >> ${_DEFINED_USERLIST}"
|
||||
done
|
||||
rlPhaseEnd
|
||||
|
||||
|
||||
rlPhaseStartTest userlist_disabled
|
||||
_make_config userlist_enable=NO
|
||||
for index in $(seq 0 0); do
|
||||
USER=${testUser[$index]}
|
||||
PASSWD=${testUserPasswd[$index]}
|
||||
_connect $USER $PASSWD
|
||||
_checkLogin
|
||||
done
|
||||
rlPhaseEnd
|
||||
|
||||
rlPhaseStartTest userlist_enabled_default
|
||||
_make_config userlist_deny=NO
|
||||
for index in $(seq 0 2); do
|
||||
USER=${testUser[$index]}
|
||||
PASSWD=${testUserPasswd[$index]}
|
||||
_connect $USER $PASSWD
|
||||
_checkLogin
|
||||
done
|
||||
for index in $(seq 3 5); do
|
||||
USER=${testUser[$index]}
|
||||
PASSWD=${testUserPasswd[$index]}
|
||||
_connect $USER $PASSWD
|
||||
_checkLogin Fail
|
||||
done
|
||||
rlPhaseEnd
|
||||
|
||||
rlPhaseStartTest userlist_enabled_defined
|
||||
_make_config userlist_file=${_DEFINED_USERLIST} userlist_deny=NO
|
||||
for index in $(seq 0 2); do
|
||||
USER=${testUser[$index]}
|
||||
PASSWD=${testUserPasswd[$index]}
|
||||
_connect $USER $PASSWD
|
||||
_checkLogin Fail
|
||||
done
|
||||
for index in $(seq 3 5); do
|
||||
USER=${testUser[$index]}
|
||||
PASSWD=${testUserPasswd[$index]}
|
||||
_connect $USER $PASSWD
|
||||
_checkLogin
|
||||
done
|
||||
rlPhaseEnd
|
||||
|
||||
rlPhaseStartTest userlist_log
|
||||
_make_config userlist_log=YES userlist_deny=NO
|
||||
for index in $(seq 0 2); do
|
||||
USER=${testUser[$index]}
|
||||
PASSWD=${testUserPasswd[$index]}
|
||||
_connect $USER $PASSWD
|
||||
_checkLogin
|
||||
done
|
||||
for index in $(seq 3 5); do
|
||||
USER=${testUser[$index]}
|
||||
PASSWD=${testUserPasswd[$index]}
|
||||
_connect $USER $PASSWD
|
||||
_checkLogin Fail
|
||||
done
|
||||
# logfile should contain 3 lines with blocked attempts
|
||||
if (( $(grep -c "User is not in the allow user list." ${_DEFAULT_DUAL_LOG}) == 3 )); then
|
||||
rlPass "Unsuccessfull logins logged successfully."
|
||||
else
|
||||
rlFail "Unsuccessfull logins failed to get logged."
|
||||
fi
|
||||
rlPhaseEnd
|
||||
|
||||
rlPhaseStartTest userlist_deny
|
||||
# userlist_deny should be by default YES
|
||||
_make_config
|
||||
# default list is now defining users to deny
|
||||
for index in $(seq 0 2); do
|
||||
USER=${testUser[$index]}
|
||||
PASSWD=${testUserPasswd[$index]}
|
||||
_connect $USER $PASSWD
|
||||
_checkLogin Fail
|
||||
done
|
||||
for index in $(seq 3 5); do
|
||||
USER=${testUser[$index]}
|
||||
PASSWD=${testUserPasswd[$index]}
|
||||
_connect $USER $PASSWD
|
||||
_checkLogin
|
||||
done
|
||||
rlPhaseEnd
|
||||
|
||||
rlPhaseStartCleanup
|
||||
if (( ${_ERRORS} != 0 )); then
|
||||
cat ${_LOG_FILE}
|
||||
fi
|
||||
CleanupDo
|
||||
rlPhaseEnd
|
||||
rlJournalPrintText
|
||||
rlJournalEnd
|
||||
4
main.fmf
4
main.fmf
|
|
@ -1,4 +0,0 @@
|
|||
# QE owner
|
||||
contact: Ondrej Mejzlik <omejzlik@redhat.com>
|
||||
check:
|
||||
- how: avc
|
||||
|
|
@ -1,6 +0,0 @@
|
|||
summary: Run all tests
|
||||
discover:
|
||||
how: fmf
|
||||
execute:
|
||||
how: tmt
|
||||
|
||||
|
|
@ -1,21 +0,0 @@
|
|||
/public:
|
||||
summary: Public other tests
|
||||
discover:
|
||||
how: fmf
|
||||
filter: 'tier: -1 & tier: -2 & tier: -3 & tag: -multihost'
|
||||
url: "https://src.fedoraproject.org/tests/vsftpd.git"
|
||||
execute:
|
||||
how: tmt
|
||||
|
||||
/internal:
|
||||
summary: Internal other tests
|
||||
discover:
|
||||
how: fmf
|
||||
filter: 'tier: -1 & tier: -2 & tier: -3 & tag: -multihost'
|
||||
url: https://gitlab.com/redhat/rhel/tests/vsftpd
|
||||
adjust:
|
||||
enabled: false
|
||||
when: distro == centos-stream or distro == fedora
|
||||
execute:
|
||||
how: tmt
|
||||
|
||||
|
|
@ -1,21 +0,0 @@
|
|||
/public:
|
||||
summary: Public Tier1 tests
|
||||
discover:
|
||||
how: fmf
|
||||
filter: 'tier: 1'
|
||||
url: "https://src.fedoraproject.org/tests/vsftpd.git"
|
||||
execute:
|
||||
how: tmt
|
||||
|
||||
/internal:
|
||||
summary: Internal Tier1 tests
|
||||
discover:
|
||||
how: fmf
|
||||
filter: 'tier: 1'
|
||||
url: https://gitlab.com/redhat/rhel/tests/vsftpd
|
||||
adjust:
|
||||
enabled: false
|
||||
when: distro == centos-stream or distro == fedora
|
||||
execute:
|
||||
how: tmt
|
||||
|
||||
|
|
@ -1,21 +0,0 @@
|
|||
/public:
|
||||
summary: Public Tier2 and Tier3 tests
|
||||
discover:
|
||||
how: fmf
|
||||
filter: 'tier: 2 | tier: 3'
|
||||
url: "https://src.fedoraproject.org/tests/vsftpd.git"
|
||||
execute:
|
||||
how: tmt
|
||||
|
||||
/internal:
|
||||
summary: Internal Tier2 and Tier3 tests
|
||||
discover:
|
||||
how: fmf
|
||||
filter: 'tier: 2 | tier: 3'
|
||||
url: https://gitlab.com/redhat/rhel/tests/vsftpd
|
||||
adjust:
|
||||
enabled: false
|
||||
when: distro == centos-stream or distro == fedora
|
||||
execute:
|
||||
how: tmt
|
||||
|
||||
Loading…
Add table
Add a link
Reference in a new issue